I don't think anything where you have to ask nicely to not mirror / broadcast stuff is naive. NIP-70 falls in that category.
I'm fine with just AUTH on the server (relay / blossom) level.
PS: That's literally a good enough solution for :90percent: of my needs. Add some encryption (sometimes), and we're good.